Secret Scan / scan (push) Successful in 6s
Build App (Preview) / compute-version (pull_request) Successful in 5s
Secret Scan / scan (pull_request) Successful in 7s
Build App (Preview) / create-release (pull_request) Successful in 3s
Build App (Preview) / build-macos (pull_request) Successful in 2m49s
Build App (Preview) / build-linux (pull_request) Successful in 5m16s
Build App (Preview) / build-windows (pull_request) Successful in 10m4s
Build App (Preview) / prune-previews (pull_request) Successful in 9s
Final-wave cleanups from the whole-branch review (final-review.md Minor 1-5): spec §4 now says selective pruning, not "deletes the directory every build"; spec §3.3 now describes the TypeScript-AST scan (fail-closed Vite-order resolution, namespace imports as member access only, the every-code-file boundary check) instead of the old regex/chunk description; the viewer spec's historical "every command is callable from every window" line gets a dated "closed by the AppManifest lockdown" note; the lib.rs doc comment on the_generated_app_manifest_matches_the_handler_list no longer claims independence from the shared parser it actually reuses; and the vitest command-name regex now allows digits, matching Rust's [a-z0-9_]+. Also adds a cargo test backstop (the_tauri_config_capability_check_runs_against_the_real_tree) that runs build.rs's tauri-config capability check against the real app/src-tauri tree on every `cargo test`, closing the gap where a new tauri.<platform>.conf.json on an already-built tree only gets checked by build.rs on a clean build. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>